PKI, Cryptography and Zero Trust Architect
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
- Develop enterprise PKI, KMS, cryptographic, and HSM architecture supporting VA operational and cybersecurity requirements.
- Architect HSM-backed roots of trust and integration with enterprise Certificate Authorities and KMS platforms.
- Design Zero Trust cryptographic controls aligned with NIST SP 800-207 and VA Critical Security Controls.
- Integrate HSM architecture with enterprise ICAM services, machine identity, authentication, authorization, and least-privilege controls.
- Design hybrid classical/post-quantum cryptographic architectures supporting phased PQC adoption.
- Architect parallel PQC/hybrid CA hierarchies to enable transition without disruption to production PKI.
- Develop approaches for cross-certification, new trust-anchor distribution, certificate issuance/validation, revocation, OCSP, and enrollment.
- Support development of the Zero Trust Implementation Plan and define measurable Zero Trust maturity targets.
- Design management-plane segmentation, mutually authenticated communications, machine identity, privileged-access controls, quorum control, and tamper-evident audit capabilities.
- Support development and maintenance of the Crypto Agility Plan and Cryptographic Bill of Materials.
- Evaluate architectural impacts of evolving NIST, IETF, CNSA 2.0, and Federal cryptographic standards.
Requirements
The position requires demonstrated experience designing and operating enterprise PKI and key-management architectures and working knowledge of FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). The candidate should be able to demonstrate prior work involving hybrid classical/PQC architectures and Zero Trust designs consistent with NIST SP 800-207. Primarily remote. Limited travel to customer facility., * Demonstrated enterprise PKI architecture and operations experience.
- Demonstrated enterprise KMS and HSM architecture experience.
- Strong understanding of Zero Trust architecture and NIST SP 800-207.
- Experience with HSM-backed roots of trust and enterprise ICAM integration.
- Working knowledge of FIPS 203, 204, and 205 and their HSM implementation implications.
- Demonstrated experience designing hybrid classical/PQC architectures or cryptographic modernization strategies.
WHAT SETS YOU APART
- CISSP-ISSAP, SABSA, TOGAF, or comparable security/architecture credentials.
- Experience with Federal ICAM/FICAM and PIV/CAC environments.
- Experience with Microsoft ADCS and enterprise certificate services.
- Experience designing PQC migration strategies for large enterprise environments., * You will be a key contributor to Iron Bow’s transformational shift in how we deliver value to both customers and employees.
- You will have the pleasure of working with passionate professionals in a culture that fosters a workplace where everyone feels respected, supported and empowered to succeed.
About the company
Iron Bow Technologies is for people who believetrust is paramount,transformation is embraced, andthe future is here,because “What we do matters!”
We are a next generation solutions provider, delivering mission success across government, healthcare, and commercial industries. Iron Bow relies on ourpassionate people,long standing partnerships, andstrategic thinkingto solve your most critical challenges.
Whether we team with clients, colleagues, or partners, we put each other first. It’s The Iron Bow Way.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Dev Digest 134 - Where pixels sing?
Trustworthy AI Starts at Deployment: 5 Checks Before You Ship
Now is the time for industrialized software development